upvote
> Microsoft has a list of IP addresses that has been used by a computer with a certain GDID, but FBI needs to get the GDID in the first place

What they did was the opposite: ask Microsoft for GDIDs used by attacker-associated IPs within several 24-hour time periods during which attack-related activity took place. Windows pings Microsoft regularly with the GDID, establishing links between your GDID and any IP addresses you use. The IP logs from Microsoft and the VPS provider showed at least 10 instances where a single VPN IP accessed the attacker's VPS and also pinged Microsoft with at least one GDID within a 24-hour period. They found a constant GDID that all instances shared. This seems to have been the most damning GDID-related evidence in the DOJ complaint [1] and yet it wasn't mentioned in the article you linked (or any other articles about this I've seen pop up on HN). It includes the diagram from the complaint (page 18) that outlines this, but devoid of context. The ngrok stuff that the article focuses on was just the cherry on top and was discussed later in the complaint.

What also becomes clear when you read the complaint is that the GDID was just one piece of the puzzle and that they had plenty of other evidence. Attacker-associated IPs were used to access the suspect's Apple, Snapchat, and Facebook accounts, at least one of which was his actual residential IP, not a VPN IP. Once they had revealed the identity of the person who owned these accounts, they were able to all-but-confirm that this was in fact the attacker.

What remains unclear even after reading the complaint is how they were so sure that the GDID they obtained visited specific websites, but honestly, at that point, they were already drowning in evidence, so I don't know if it matters that much. It could be as simple as "he was signed into Edge with his Microsoft account and had sync enabled".

[1] https://www.justice.gov/usao-ndil/media/1450651/dl?inline

reply
Wait, so it would have, ironically, been safer to allow microsoft telemetry to bypass the VPN entirely and remain associated only with their home network, because it's the phone home to microsoft tunneled through the VPN that tied together all their IP addresses to a single microsoft account. The GDID itself is almost a red herring, as it could have been a session id or username or something only long lived enough to appear comming from several ip addresses to windows update request?
reply
They make the default web browser on Windows, and that sends your browsing data if you don't disable its telemetry.

See https://news.ycombinator.com/item?id=48921595

reply
This seems like something that should be easy to confirm, but I haven't seen anyone do it. Do they keep a database of every website visit all Edge users make?
reply
Speculation: if you turn on browser sync so you can have your open tabs and history on different computers, that stuff will be on MS' cloud with your consent, with whatever E2EE they have or claim to have.

But it would be very foolish for a blackhat to turn on browser sync...

reply
I got banned from all computers in my secondary school and from taking the IT GCSE; final school exam in the UK.

Using the school news paper shared account, I copied the bullies coursework in to the public share, made changes to the coursework on my own user account and then copied it back to their work folder using the school news papers account.

MS Office keeps an "Last edited by" field so I got caught. If I had used the school newspaper account to make the edit I wouldn't of been caught. Rookie error. I too discovered a DCOM in the Windows 98 help file that revealed all the hidden shares on the network which scared the school. This was 2004 and I was 15.

Oh and the time, I bought a BB gun off someone at school. I was a librarian in the schools library and showed it off someone of the older grade year. The head librarian confiscated it and reported it to the headmaster. The guy then gave me a copy of Q3A and I stuck with violence the video-game way.

reply
The question you should be asking is: why would Microsoft not do this?
reply
Well for one it is illegal in the EU at least, not that Microsoft or other U.S tech giants care about laws.
reply
I’m a fan of technical facts coming from technical analysis, not armchair speculation about motives.
reply
GDPR compliance.

Not in the US, of course.

reply
They didn’t. They went to ngrok and asked for all the data at the point of signup. They then looked to find the any of that data at the second site. In this case they had two identical data points - the GDID and the IP address.
reply
What do you mean? The FBI could know that this VPN ip visited ngrok and then the retailer website, but how would it know that that ip was associated with the specific GDID unless microsoft was tracking (timestamp,website,gdid) tuples?
reply
It's called telemetry. It means Windows sends data back to Microsoft about what you're doing.
reply
Have some light reading:

"required" spyware: https://learn.microsoft.com/en-us/windows/privacy/required-d...

"optional" (but on by default) spyware: https://learn.microsoft.com/en-us/windows/privacy/optional-d...

This is my favorite:

  Data Description for Browsing History data type

  Microsoft browser data subtype: Information about Address bar and Search box performance on the device

   * Text typed in Address bar and Search box
   * Service response time
   * Autocompleted text, if there was an autocomplete
   * Navigation suggestions provided based on local history and favorites
   * Browser ID
   * URLs (may include search terms)
   * Page title and notification text
reply
None of this matters really.

This criminal mastermind got caught because he did everything but sign his name to the crimes while holding two pieces of government identification in presence of a notary.

The FBI did the bare minimum in terms of old-fashioned detective work, and correlated evidence from various sources.

The obsession with GDID is a complete nothing-burger and I'm tired of seeing it on the front page every other day.

reply
I'd take all of this with a cup of salt due to law enforcement's use of parallel construction in tech cases.
reply
Wouldn't the evidence need to be presented to the defense for scrutiny, and if it turned out to be bunk, that would strongly hurt the state's case?
reply
They claim it was an ngrok account that was used to host an endpoint used in the compromise, tied to a microsoft account / gdid that was passed when ngrok software was downloaded from the "microsoft store".
reply
That wouldn't explain how they connected the GDID to the visit to the retailers website

> Three hours later, the same GDID visited the retailer’s own website, through the same Tzulo proxy address used to set up the ngrok account.

reply